Cross Site Scripting Vulnerability in D-Link DIR-816 by D-Link
CVE-2025-1392
5.1MEDIUM
Summary
A vulnerability exists in the D-Link DIR-816 router, specifically in the functionality accessed through /cgi-bin/webproc?getpage=html/index.html&var:menu=24gwlan&var:page=24G_basic. By manipulating the SSID argument, an attacker can execute cross site scripting attacks remotely. This vulnerability affects devices that are no longer supported by D-Link, allowing potential exploitation due to its public disclosure.
Affected Version(s)
DIR-816 1.01TO
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Fergod (VulDB User)